[nsp-sec] 2-byte UDP packets

Salusky, William william.salusky at corp.aol.com
Tue Oct 13 17:29:12 EDT 2009


I recall 2-byte UDP payloads as being very common proxy bot phone home
mechanisms (mitglieder) which involved many random destinations
presumably intended to complicate the identification of active proxybot
controller.
 
----
William Salusky 
William.Salusky at corp.aol.com
Principal Technical Security Engineer - AOL Information Technology
Security CERT team
703-265-4924 (office) : 571-480-1933 (mobile) 
 
 

> -----Original Message-----
> From: nsp-security-bounces at puck.nether.net 
> [mailto:nsp-security-bounces at puck.nether.net] On Behalf Of 
> Sidney Faber
> Sent: Tuesday, October 13, 2009 3:54 PM
> To: 'nsp-security at puck.nether.net'
> Subject: [nsp-sec] 2-byte UDP packets
> 
> ----------- nsp-security Confidential --------
> 
> 



More information about the nsp-security mailing list